A Russia-linked threat actor known as Callisto, also referred to as ColdRiver or Star Blizzard, attempted to compromise the nonprofit organization Reporters Without Borders (RSF) through a sophisticated phishing campaign. The attack involved credential-harvesting tactics, including the use of a ProtonMail account impersonating a trusted contact and a lure referencing a missing file. The phishing email, written in French and using a legitimate signature, prompted the recipient to request a follow-up document, after which a malicious link was sent. This link redirected the target to a spoofed ProtonMail login page designed to steal credentials. The campaign leveraged advanced adversary-in-the-middle (AiTM) phishing techniques and social engineering, with the attacker switching languages and using compromised websites to host malicious content.
RSF, which supports journalists under threat and has been labeled an "undesirable organization" by the Kremlin, was specifically targeted, highlighting the ongoing focus of Russian APTs on NGOs and organizations supporting Ukraine. The attack was ultimately thwarted when ProtonMail blocked the attacker's account, preventing the malicious file from being delivered. Security researchers noted that similar lures were used against other organizations, and the campaign reflects a broader trend of Russian APTs using custom phishing kits and social engineering to target high-profile entities. The incident underscores the persistent threat posed by Russian state-aligned actors to civil society organizations and the need for robust email security and user awareness training.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In August 2025, Russian authorities labeled Reporters Without Borders an 'undesirable organization,' effectively criminalizing its activities in Russia. The designation added political context to the earlier targeting of the NGO.
In a related campaign reported in the same timeframe, Callisto targeted another unnamed organization with a decoy PDF and a spoofed ProtonMail login page designed to steal credentials. The activity showed the group reusing a custom adversary-in-the-middle phishing approach.
During the March 2025 operation against Reporters Without Borders, ProtonMail blocked the attacker-controlled account before the malicious PDF could be delivered. This prevented the phishing attempt from fully executing.
In March 2025, the Russia-linked threat actor Callisto (also known as ColdRiver or Star Blizzard) targeted Reporters Without Borders with a phishing email sent from a ProtonMail account impersonating a trusted contact. The lure used a 'missing file' pretext to prompt a reply and set up delivery of a malicious link via a compromised website.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.